Codex ships its own RG version which triggers MacOS safety standards
What version of Codex CLI is running?
0.144.1
What subscription do you have?
PRO and PLUS
Which model were you using?
sol
What platform is your computer?
Darwin 25.5.0 arm64 arm
What terminal emulator and version are you using (if applicable)?
Ghostty
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1783692029s since unix epoch",
"overallStatus": "ok",
"codexVersion": "0.144.1",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "/Users/bedas/.codex/app-server-control/app-server-control.sock",
"daemon state dir": "/Users/bedas/.codex/app-server-daemon",
"mode": "ephemeral",
"pid file": "/Users/bedas/.codex/app-server-daemon/app-server.pid (missing)",
"settings": "/Users/bedas/.codex/app-server-daemon/settings.json (missing)",
"status": "not running",
"update-loop pid file": "/Users/bedas/.codex/app-server-daemon/app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 0
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is configured",
"details": {
"auth file": "/Users/bedas/.codex/auth.json",
"auth storage mode": "Keyring",
"stored API key": "false",
"stored ChatGPT tokens": "true",
"stored agent identity": "false",
"stored auth mode": "chatgpt"
},
"remediation": null,
"durationMs": 3
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "/Users/bedas/.codex",
"config.toml": "/Users/bedas/.codex/config.toml",
"config.toml parse": "ok",
"cwd": "/Users/bedas/Developer/source/git/nautilus/praxis",
"enabled feature flags": "shell_tool, unified_exec, shell_snapshot, code_mode_host, terminal_resize_reflow, sqlite, hooks, enable_request_compression, apps, tool_search_always_defer_mcp_tools, tool_suggest, plugins, in_app_browser, browser_use, browser_use_full_cdp_access, browser_use_external, computer_use, remote_plugin, plugin_sharing, image_generation, resize_all_images, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, auth_elicitation, personality, tui_app_server, prevent_idle_sleep, remote_compaction_v2, workspace_dependencies",
"feature flag overrides": "multi_agent=false, fast_mode=false, prevent_idle_sleep=true",
"feature flags enabled": "34",
"log dir": "/Users/bedas/.codex/log",
"mcp servers": "3",
"model": "gpt-5.6-sol",
"model provider": "openai",
"sqlite home": "/Users/bedas/.codex"
},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git version 2.50.1 (Apple Git-155)",
"details": {
".git entry": "directory",
"PATH git #1": "/usr/bin/git",
"PATH git entries": "1",
"git branch": "main",
"git build options": "git version 2.50.1 (Apple Git-155); cpu: arm64; no commit associated with this build; sizeof-long: 8; sizeof-size_t: 8; shell-path: /bin/sh; feature: fsmonitor--daemon; libcurl: 8.7.1; zlib: 1.2.12; SHA-1: SHA1_DC; SHA-256: SHA256_BLK",
"git exec path": "/Applications/Xcode.app/Contents/Developer/usr/libexec/git-core",
"git version": "git version 2.50.1 (Apple Git-155)",
"repo detected": "true",
"repo root": "/Users/bedas/Developer/source/git/nautilus/praxis",
"selected git": "/usr/bin/git"
},
"remediation": null,
"durationMs": 130
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "/opt/homebrew/bin/codex",
"current executable": "/opt/homebrew/bin/codex",
"install context": "brew (package /opt/homebrew/Caskroom/codex/0.144.1, bin /opt/homebrew/Caskroom/codex/0.144.1/bin, resources /opt/homebrew/Caskroom/codex/0.144.1/codex-resources, path /opt/homebrew/Caskroom/codex/0.144.1/codex-path)",
"managed by bun": "false",
"managed by npm": "false",
"managed by pnpm": "false",
"managed package root": "not set"
},
"remediation": null,
"durationMs": 3
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "ok",
"summary": "MCP configuration is locally consistent",
"details": {
"configured servers": "3",
"disabled servers": "0",
"stdio servers": "1",
"streamable_http servers": "2"
},
"remediation": null,
"durationMs": 4906
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"proxy env vars": "none"
},
"remediation": null,
"durationMs": 0
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 404)",
"reachability mode": "ChatGPT auth"
},
"remediation": null,
"durationMs": 353
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket handshake succeeded",
"details": {
"DNS": "2 IPv4, 2 IPv6, first IPv6",
"auth mode": "chatgpt",
"connect timeout": "15000 ms",
"endpoint": "wss://chatgpt.com/backend-api/<redacted>",
"handshake result": "HTTP 101 Switching Protocols",
"model provider": "openai",
"models etag present": "true",
"provider name": "OpenAI",
"proxy env vars": "none",
"reasoning header": "false",
"server model present": "false",
"supports websockets": "true",
"wire API": "responses"
},
"remediation": null,
"durationMs": 838
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running brew on macos-aarch64",
"details": {
"commit": "unknown",
"current executable": "/opt/homebrew/bin/codex",
"install method": "brew (package /opt/homebrew/Caskroom/codex/0.144.1, bin /opt/homebrew/Caskroom/codex/0.144.1/bin, resources /opt/homebrew/Caskroom/codex/0.144.1/codex-resources, path /opt/homebrew/Caskroom/codex/0.144.1/codex-path)",
"platform": "macos-aarch64",
"version": "0.144.1"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search is OK (bundled)",
"details": {
"search command": "/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "OnRequest",
"codex-linux-sandbox helper": "none",
"execve wrapper helper": "/Users/bedas/.codex/tmp/arg0/codex-arg0YpJR1E/codex-execve-wrapper",
"filesystem sandbox": "restricted",
"network sandbox": "restricted"
},
"remediation": null,
"durationMs": 0
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "/Users/bedas/.codex (dir)",
"active rollout files": "1708 files, 1559307974 total bytes, 912943 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "/Users/bedas/.codex/goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "/Users/bedas/.codex/logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "/Users/bedas/.codex/log (dir)",
"memories DB": "/Users/bedas/.codex/memories_1.sqlite (file)",
"memories DB integrity": "ok",
"sqlite home": "/Users/bedas/.codex (dir)",
"state DB": "/Users/bedas/.codex/state_5.sqlite (file)",
"state DB integrity": "ok"
},
"remediation": null,
"durationMs": 632
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "openai",
"rollout DB active files": "1708",
"rollout DB active rows": "1708",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "openai=1708",
"rollout DB rows": "1708",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "vscode=708, subagent:other=525, cli=280, subagent:review=104, exec=42, mcp=39, subagent:thread_spawn=10",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 6722
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language en-US",
"details": {
"EDITOR": "set",
"LANG": "en_US.UTF-8",
"VISUAL": "set",
"os": "Mac OS 26.5.1 [64-bit]",
"os language": "en-US",
"os type": "Mac OS",
"os version": "26.5.1"
},
"remediation": null,
"durationMs": 2
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"COLORTERM": "truecolor",
"TERM": "xterm-ghostty",
"TERMINFO": "/Applications/Ghostty.app/Contents/Resources/terminfo (dir)",
"TERM_PROGRAM": "ghostty",
"color output": "enabled",
"effective locale": "en_US.UTF-8",
"multiplexer": "tmux 3.7b",
"stderr is terminal": "true",
"stdin is terminal": "true",
"stdout is terminal": "true",
"terminal": "Ghostty",
"terminal size": "119x58",
"terminal version": "1.3.1",
"tmux allow-passthrough": "off",
"tmux client termname": "xterm-ghostty",
"tmux client termtype": "ghostty 1.3.1",
"tmux extended-keys": "always",
"tmux focus-events": "on",
"tmux set-clipboard": "on",
"tmux xterm-keys": "on"
},
"remediation": null,
"durationMs": 40
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title configured",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, run-state, model, task-progress",
"terminal title source": "configured"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.143.0",
"check for update on startup": "true",
"last checked at": "2026-07-09T17:47:45.793260Z",
"latest version": "0.144.1",
"latest version status": "current version is not older",
"update action": "brew upgrade --cask codex",
"version cache": "/Users/bedas/.codex/version.json"
},
"remediation": null,
"durationMs": 681
}
}
}
What issue are you seeing?
Codex ships its own RG version:
Ran command -V rg
└ rg is /opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg
This immediately triggers mac's safety net and pops up a modal telling you RG is unverifiable and thus has to be deleted.
It should, instead, use the OS's RG and tell users to install it or whatever if you really insist having it, or at least fall back to that when installed
command -V rg
rg is /opt/homebrew/bin/rg
The current situation is unbearable and will trigger a warning on each and every codex interaction that even remotely reads something from disk.
What steps can reproduce the bug?
Open codex CLI, have it do some work and see the failure as soon it tries to run rg
What is the expected behavior?
A cli should not bundle independently available tools - instead if anything it should install them as a dependency and not bundle an unverifiable package
Additional information
Codex 0.144.1 is placing an ad-hoc-signed, quarantined, Gatekeeper-rejected executable ahead of the working /opt/homebrew/bin/rg.
xattr -l "$RG"
com.apple.provenance:
com.apple.quarantine: 0381;6a50e9a1;;F87AE0CE-FD19-4389-9A63-7E0846E16A6F
bedas@apollo praxis % codesign -dv --verbose=4 "$RG" 2>&1
Executable=/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg
Identifier=rg
Format=Mach-O thin (arm64)
CodeDirectory v=20400 size=31483 flags=0x20002(adhoc,linker-signed) hashes=981+0 location=embedded
VersionPlatform=1
VersionMin=720896
VersionSDK=984320
Hash type=sha256 size=32
CandidateCDHash sha256=a7dbf01facbbddf9e0356a5cefb5af62452a2c78
CandidateCDHashFull sha256=a7dbf01facbbddf9e0356a5cefb5af62452a2c782365f05fc472e748cad3ef63
Hash choices=sha256
CMSDigest=a7dbf01facbbddf9e0356a5cefb5af62452a2c782365f05fc472e748cad3ef63
CMSDigestType=2
Executable Segment base=0
Executable Segment limit=3751936
Executable Segment flags=0x1
Page size=4096
CDHash=a7dbf01facbbddf9e0356a5cefb5af62452a2c78
Signature=adhoc
Info.plist=not bound
TeamIdentifier=not set
Sealed Resources=none
Internal requirements=none
bedas@apollo praxis % spctl --assess --type execute --verbose=4 "$RG"
/opt/homebrew/Caskroom/codex/0.144.1/codex-path/rg: rejected
This does not prove malware, but it is unquestionably broken distribution and poor security UX. Mac users should not have to waive Gatekeeper for a hidden helper binary.
7 Comments
Temporary easiest solution, put this in your local agents.md or as part of prompt or whatever you like to instruct the llm:
This has a slight token overhead but is minimal and lets you use the tool adequately.
Confirmed independently on macOS 26.4.1 (25E253), arm64, with Codex CLI 0.144.1 installed via Homebrew Cask.
The bundled helper resolved first on
PATH:It had the same ad-hoc signature/CDHash reported above (
a7dbf01facbbddf9e0356a5cefb5af62452a2c78), carriedcom.apple.quarantine, and was rejected byspctl. The separately installed/opt/homebrew/bin/rg15.1.0 worked normally.One additional packaging datapoint: quarantine was not limited to
rg; it was present across the versioned Caskroom tree and on all four shipped executables:bin/codexbin/codex-code-mode-hostcodex-path/rgcodex-resources/zsh/bin/zshcodexandcodex-code-mode-hosthad valid Developer ID signatures from OpenAI (TeamIdentifier=2DC432GLL2). The bundledrgandzshwere only ad-hoc signed.codesign --verifypassed for all four, so this looked like quarantine/Gatekeeper distribution behavior rather than file corruption.Removing
com.apple.quarantinefrom each executable resolved the prompts. Afterward,codex --version,codex --help,codex exec --help,codex-code-mode-host --help, the bundled zsh, and bundledrg --versionall completed successfully. Homebrew reported no missing dependencies or partial installation.This suggests the release/cask fix should cover every executable helper in the packaged tree, not only
rg; otherwise another bundled helper may trigger the same behavior later.I disagree. The release should not bundle things that should be installed as dependencies. Literally this is what package managers are for. Codex can request zsh, rg, or whatever else it pleases to be installed through brew. This is how other tools do it (say, if you install openssl it will pull some other stuff too, not bundle it)
Similarly, in a python app you are not bundling python libs, you write a requirements.txt that pip installs for it on venv, for example.
PS: I might misunderstand what you mean, it sounds like you suggest they should keep shipping it bundled, but signed.
---
That said, thanks for adding those other details, I could not find but feared there might be more.
I can reproduce this on macOS with Codex CLI 0.144.1 installed via Homebrew Cask.
macOS shows a Gatekeeper dialog:
The bundled Codex
rgis selected ahead of the normal Homebrew ripgrep:The separately installed Homebrew ripgrep at
/opt/homebrew/bin/rgis present, but Codex prepends its bundledcodex-path/rg, which macOS blocks. This makes searches fail until the bundled binary's quarantine/signing issue is worked around.Duplicate of https://github.com/openai/codex/issues/28190.
I recomend that you update to the latest version of codex
https://learn.chatgpt.com/docs/codex/cli#getting-started
<img width="1128" height="774" alt="Image" src="https://github.com/user-attachments/assets/639819bc-ec15-4b59-b20c-1ddfb081402c" />
The commands now resolve to host-installed packages, not Codex-bundled copies:
The issue seems resolved - probably until the next release only tho.